Semiconductor apparatus, and fault injection determination method

The semiconductor device configuration with a fault injection detector, cryptographic module, and controller addresses the challenge of distinguishing between legitimate fault injections and noise, thereby reducing false detections and maintaining cryptographic performance.

JP2025095198APending Publication Date: 2025-06-26RENESAS ELECTRONICS CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023211045
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing fault injection detectors in semiconductor devices, such as analog sensors and digital detectors, struggle to distinguish between voltage glitches, electromagnetic wave irradiation, and noise, leading to false detections of fault injections.

Method used

A semiconductor device configuration that includes a fault injection detector, a cryptographic module, and a controller. The controller verifies the cryptographic data generated by the cryptographic module when a fault injection is detected, using methods like the Doubling method or the Verification method to differentiate between valid and invalid data.

Benefits of technology

This configuration effectively suppresses false detection of fault injections, reducing the risk of misidentifying noise or simple voltage fluctuations as fault injections, while maintaining the cryptographic processing performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025095198000001_ABST
    Figure 2025095198000001_ABST
Patent Text Reader

Abstract

To make it possible to suppress erroneous detection of fault injection.SOLUTION: A fault injection detector 103 detects fault injection. An encryption module 125 encrypts a plain text to thereby generate first encryption data. When the fault injection detector 103 detects any fault injection, a controller 121 verifies the encryption data generated by the encryption module 125 to determine whether or not the encryption data is correct.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a semiconductor device and a fault injection determination method, and more particularly to a semiconductor device having a functional unit that performs cryptographic processing, and a fault injection determination method in such a semiconductor device.

Background Art

[0002] Cryptographic techniques are used for secure communication and data confidentiality. Encryption techniques have been widely adopted in personal information devices such as IC (Integrated Circuit) cards. In recent years, the importance of cryptographic techniques has also increased in ECUs (Electronic Control Units) installed inside automobiles to electronically control each part of the vehicle.

[0003] However, even though cryptographic techniques are logically secure, fault attacks targeting physical vulnerabilities such as differential fault analysis (DFA) pose a realistic threat. In a DFA attack, an attacker instantaneously applies an abnormal voltage such as a power glitch to an electronic device equipped with a cryptographic technique. The attacker intentionally causes a faulty operation to obtain a correct ciphertext and a ciphertext containing an error. The attacker analyzes the difference between the correct ciphertext and the ciphertext containing an error to estimate the secret key.

[0004] As a countermeasure against fault attacks, a fault injection detector that detects fault injection such as a power glitch or electromagnetic wave irradiation is known. For example, Non-Patent Document 1 discloses an analog sensor used in a fault injection detector. Non-Patent Document 2 also discloses a digital detector used in a fault injection detector.

Prior Art Documents

Non-Patent Documents

[0005]

Non-Patent Document 1

[0006] As a fault injection detector, the analog sensor and the digital detector are known. However, for both the analog sensor and the digital detector, it is difficult to distinguish between voltage glitches, electromagnetic wave irradiation, and noise, and there has been a problem of misdetecting simple voltage fluctuations as fault injections.

[0007] Other problems and novel features will become apparent from the description of this specification and the accompanying drawings. [Means for Solving the Problems]

[0008] According to one embodiment, a semiconductor device is provided. The semiconductor device includes a fault injection detector, a cryptographic module, and a controller. The controller verifies the cryptographic data generated by the cryptographic module when a fault injection is detected in the fault injection detector.

Advantages of the Invention

[0009] According to the above-described embodiment, false detection of fault injection can be suppressed.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Mode for Carrying Out the Invention

[0011] Prior to the description of the embodiment, the process of arriving at the following embodiment will be described. As a countermeasure against DFA attacks, a configuration is conceivable in which the generated ciphertext is verified, and when the ciphertext is confirmed to be valid, the ciphertext is output. As a method for verifying the ciphertext, the Doubling method is known in which encryption processing is performed twice on the plaintext and the results are compared. Also, as a method for verifying the ciphertext, the Verification method is known in which decryption processing is performed on the encrypted data obtained by encrypting the plaintext, and the decrypted data is compared with the original plaintext.

[0012] However, the Doubling method has a problem that two cryptographic circuits need to be implemented, resulting in a doubling of the implementation cost. In addition, the Verification method has a problem that since decryption processing needs to be performed after encryption, the arithmetic performance of the cryptographic processing is substantially reduced by 1 / 2. In order to reduce at least a part of the above problems, the inventor of the present invention has come up with the following embodiments.

[0013] Hereinafter, embodiments applying means for solving the above problems will be described in detail with reference to the drawings. For clarity of explanation, the following description and drawings are appropriately omitted and simplified. In each drawing, the same reference numerals are assigned to the same elements, and duplicate explanations are omitted as necessary.

[0014] In the following embodiments, when necessary for convenience, they are divided and described in a plurality of sections or embodiments. However, unless otherwise specified, they are not unrelated to each other. One is a modification, application example, detailed explanation, or supplementary explanation of a part or all of the other. Also, in the following embodiments, when referring to the number of elements, etc. (including the number, numerical value, quantity, and range, etc.), unless otherwise specified and in principle clearly limited to a specific number, it is not limited to that specific number, and it may be more than or less than the specific number.

[0015] Furthermore, in the following embodiments, the components (including operation steps, etc.) are not necessarily essential unless otherwise specified and in principle clearly considered essential. Similarly, in the following embodiments, when referring to the shape, positional relationship, etc. of components, etc., unless otherwise specified and in principle clearly considered otherwise, those substantially approximating or similar to the shape, etc. are included. This also applies to the above numbers, etc. (including the number, numerical value, quantity, and range).

[0016] [Embodiment 1] FIG. 1 shows a configuration example of a semiconductor device according to Embodiment 1 of the present disclosure. The semiconductor device 100 shown in FIG. 1 includes a host 101, a security IP (Intellectual Property) 102, and a fault injection detector 103. In the present embodiment, the semiconductor device 100 is configured as, for example, a SoC (System on Chip) device. The semiconductor device 100 is mounted on a vehicle and can be used for an ECU or the like that controls each part of the vehicle. Although not shown in FIG. 1, the semiconductor device 100 has external interfaces such as a power supply terminal and a clock terminal.

[0017] The host 101 performs various processes in the semiconductor device 100. The host 101 may have, for example, one or more processors and one or more memories. In the host 101, the processor executes processes according to a program read from the memory to perform various processes. The processes performed by the host 101 include a process of requesting data encryption from the security IP 102. When the host 101 requests data encryption from the security IP 102, the host 101 transmits an encryption process instruction command and the data to be encrypted, that is, plaintext data, to the security IP 102.

[0018] The security IP 102 is a functional unit that performs encryption processing. The security IP 102 receives an encryption process instruction command and plaintext data from the host 101. The security IP 102 encrypts the plaintext data added to the encryption process instruction command and outputs the encrypted data to the host 101. The security IP 102 may receive a decryption process command from the host 101. In that case, the security IP 102 decrypts the encrypted data input from the host 101 and outputs the decrypted data to the host 101.

[0019] The fault injection detector 103 detects fault injection. In the present embodiment, a known detection method can be used as the detection method of fault injection used in the fault injection detector 103. The fault injection detector 103 is mounted corresponding to a portion targeted for a fault injection attack in the semiconductor device 100, for example. In the present embodiment, it is assumed that the fault injection detector 103 is mounted corresponding to an external power supply terminal. Specifically, the fault injection detector 103 is mounted in the vicinity of the external power supply terminal, for example, within a predetermined distance from the external power supply terminal.

[0020] In the present embodiment, a glitch attack on the power supply terminal is assumed as the fault injection. The semiconductor device 100 is supplied with a power supply voltage VCC from the external power supply terminal. In the semiconductor device 100, the host 101 and the security IP 102 operate with the power supply voltage VCC. The fault injection detector 103 monitors the power supply voltage VCC and detects a voltage glitch. When the fault injection detector 103 detects a fault injection, it outputs a fault detection signal to the host 101. When the host 101 receives the fault detection signal, it outputs a verification instruction command to the security IP 102.

[0021] The security IP 102 includes a controller 121, an encryption module 125, and a comparator 130. The controller 121 controls the operations of the security IP 102 and the comparator 130. The controller 121 includes a command reception unit 122 and a verification unit 123. The command reception unit 122 receives a command from the host 101 and decodes the received command. When the received command is an encryption processing instruction command, the command reception unit 122 instructs the encryption module 125 to encrypt the plaintext data added to the encryption processing instruction command.

[0022] When the received command is a verification instruction command, the command reception unit 122 instructs the verification unit 123 to perform verification of the encrypted data. For example, when a verification instruction command is input when encrypted data is generated in the encryption module 125, the command reception unit 122 instructs the verification unit 123 to perform verification of the encrypted data. When verification is instructed, the verification unit 123 enables the encryption data verification function in the security IP 102. In this embodiment, it is assumed that the Doubling method is used for verification of the encrypted data. When verification is instructed, the verification unit 123 enables the Doubling function. The verification unit 123 enables the Doubling function, for example, by outputting a predetermined signal for enabling the Doubling function to the encryption module 125 and the comparator 130. The controller 121 can be configured using at least one of a hardware sequencer and a CPU.

[0023] The encryption module 125 includes a buffer 126 and an encryption processing unit 127. The buffer 126 stores data to be encrypted, that is, plaintext data. The encryption processing unit 127 encrypts the plaintext data stored in the buffer 126. The encryption processing unit 127 encrypts the plaintext data using a predetermined encryption method such as AES (Advanced Encryption Standard), for example. The encryption processing unit 127 transfers the data obtained by encrypting the plaintext data, that is, the encrypted data, to the comparator 130.

[0024] The comparator 130 includes a register 131. The register 131 stores the encrypted data transferred from the encryption processing unit 127. The encrypted data stored in the register 131 is also referred to as first encrypted data. When the Doubling function is not enabled, the controller 121 transmits the encrypted data encrypted by the encryption module 125 to the host 101. The controller 121 reads the encrypted data from the register 131 and transmits the read encrypted data to the host 101, for example.

[0025] When the Doubling function is enabled, the verification unit 123 instructs the encryption module 125 to re-encrypt the plaintext data. When the Doubling function is enabled, the encryption processing unit 127 encrypts the plaintext data stored in the buffer 126 again and transfers the re-encrypted encrypted data to the comparator 130. The re-encrypted encrypted data is also called the second encrypted data. When the Doubling function is enabled, the comparator 130 compares the encrypted data stored in the register 131 with the re-encrypted encrypted data. When the Doubling function is enabled, the register 131 may store the first encrypted data and the re-encrypted encrypted data.

[0026] The controller 121 verifies the encrypted data stored in the register 131 according to the comparison result in the comparator 130, and determines whether the encrypted data is valid. The controller 121 determines whether to send the encrypted data to the host 101 or suppress the transmission of the encrypted data to the host 101 according to the verification result of the encrypted data. When the comparison result that the two encrypted data match is obtained in the comparator 130, the controller 121 determines that the encrypted data is valid and sends the encrypted data to the host 101. When the comparison result that the two encrypted data do not match is obtained in the comparator 130, the controller 121 determines that the encrypted data is not valid. In that case, the controller 121 notifies the host 101 of an error without sending the encrypted data to the host 101.

[0027] [Operation procedure] Figure 2 shows the operation procedure in the semiconductor device 100. At least a part of the operation procedure shown in Figure 2 corresponds to the fault injection determination method. The host 101 transmits an encryption processing instruction command and plaintext data to the security IP 102. In the security IP 102, the controller 121 receives the encryption processing instruction command transmitted from the host 101 (step A1). In step A1, the command reception unit 122 of the controller 121 decodes the command received from the host 101 and recognizes that the received command is an encryption processing instruction command.

[0028] The controller 121 transfers the plaintext data added to the encryption processing instruction command to the encryption module 125 (step A2). The encryption module 125 stores the transferred plaintext data in the buffer 126. The encryption processing unit 127 encrypts the plaintext data stored in the buffer 126 (step A3). The encryption processing unit 127 transfers the encrypted data encrypted in step A3 to the comparator 130 (step A4). The comparator 130 stores the transferred encrypted data in the register 131.

[0029] The controller 121 determines whether a fault injection has been detected (step A5). If a fault injection is detected between step A1 and step A4, the fault injection detector 103 outputs a fault detection signal to the host 101. When the host 101 receives the fault detection signal, it transmits a verification instruction command to the security IP 102. When the controller 121 receives the verification instruction command from the host 101, in step A5, it determines that a fault injection has been detected. When the controller 121 has not received the verification instruction command from the host 101, it determines that no fault injection has been detected.

[0030] If it is determined in step A5 that no fault injection is detected, the controller 121 reads out the encrypted data stored in the register 131 of the comparator 130. The controller 121 transmits the read encrypted data to the host 101 (step A10). The host 101 acquires the encrypted data from the security IP 102.

[0031] If it is determined in step A5 that a fault injection is detected, the verification unit 123 of the controller 121 instructs the encryption module 125 to re-encrypt the plaintext data. In the encryption module 125, the encryption processing unit 127 re-encrypts the plaintext data stored in the buffer 126 (step A6). The encryption processing unit 127 transfers the encrypted data encrypted in step A6 to the comparator 130 (step A7).

[0032] The comparator 130 compares the encrypted data stored in the register 131 with the encrypted data transferred in step A7 (step A8). The verification unit 123 reads out the comparison result of the comparator 130 and determines whether the encrypted data matches (step A9). If the verification unit 123 determines that the encrypted data does not match, it determines that the encrypted data is not valid and that a fault injection attack has been performed. In that case, the controller 121 notifies the host 101 of an error (step A11). If the verification unit 123 determines in step A9 that the encrypted data matches, it determines that the fault injection has been misdetected due to noise or the like. In that case, the process proceeds to step A10, and the controller 121 transmits the encrypted data to the host 101.

[0033] [Summary] In this embodiment, the fault injection detector 103 detects a fault injection. In this embodiment, when a fault injection is detected, the encryption module 125 verifies the validity of the encrypted data by the Doubling method. In this embodiment, even if a fault injection is misdetected due to noise, if the encrypted data is determined to be valid, the security IP 102 transmits the encrypted data to the host 101.

[0034] In this embodiment, the encryption module 125 only needs to perform the encryption process twice when a fault injection is detected by the fault injection detector 103, and it is not necessary to always perform the encryption process twice. For this reason, the encryption module 125 does not need to have two encryption processing units 127. In this embodiment, it is sufficient that one encryption processing unit 127 is implemented in the encryption module 125, and this embodiment can suppress an increase in the implementation cost of the encryption processing unit. Also, this embodiment can reduce power consumption compared to the case where two encryption processing units 127 are implemented. In this embodiment, the security IP 102 can distinguish between a misdetection caused by noise and a detection caused by a fault injection attack by combining the detection result of the fault injection detector 103 and the verification result of the encrypted data. For this reason, this embodiment can suppress a misdetection of a fault injection without an increase in the implementation cost of the encryption processing unit.

[0035] [Second Embodiment] FIG. 3 shows a configuration example of a semiconductor device according to Embodiment 2 of the present disclosure. In this embodiment, the configuration of the security IP 102a included in the semiconductor device 100a is different from the configuration of the security IP 102 included in the semiconductor device 100 according to Embodiment 1 shown in FIG. 1. In this embodiment, the difference from Embodiment 1 is that the Verification method is used for verifying the encrypted data.

[0036] In this embodiment, when the command reception unit 122 of the controller 121 determines that the received command is a verification instruction command, it instructs the verification unit 123 to perform verification of the encrypted data. When verification is instructed, the verification unit 123 enables the Verification function. The verification unit 123 enables the Verification function, for example, by outputting a predetermined signal for enabling the Verification function to the encryption module 125a and the comparator 130a.

[0037] In this embodiment, the encryption module 125a includes a buffer 126, an encryption processing unit 127, and a selector 128. The comparator 130a includes a register X132 and a register Y133. The selector 128 selects, according to the select signal output from the controller 121, the path of the plaintext data stored in the buffer 126 or the path of the data input from the controller 121. When the Verification function is not enabled, the selector 128 selects the path of the plaintext data stored in the buffer 126. In that case, the encryption processing unit 127 encrypts the plaintext data input via the selector 128 to generate encrypted data. The encryption processing unit 127 transfers the encrypted data to the comparator 130a. In the comparator 130a, the register X132 stores the transferred encrypted data.

[0038] When the Verification function is enabled, the controller 121 changes the select signal output to the selector 128 to cause the selector 128 to select the path of the data input from the controller 121. Further, the controller 121 reads the encrypted data from the register X132 and inputs it to the selector 128 of the encryption module 125a. The selector 128 selects the path of the data input from the controller 121 and outputs the encrypted data to the encryption processing unit 127. The encryption processing unit 127 performs decryption processing on the input encrypted data to generate decrypted data. The encryption processing unit 127 transfers the decrypted data to the comparator 130a. In the comparator 130a, the register Y133 stores the transferred decrypted data.

[0039] When the verification function is enabled, the controller 121 acquires plaintext data from the buffer 126 of the encryption module 125a. The controller 121 transfers the acquired plaintext data to the comparator 130a. The comparator 130a compares the transferred plaintext data with the decrypted data stored in the register Y133.

[0040] The controller 121 verifies the encrypted data stored in the register X132 according to the comparison result in the comparator 130a, and determines whether the encrypted data is valid. When the comparison result that the plaintext data and the decrypted data match is obtained in the comparator 130a, the controller 121 determines that the encrypted data is valid. In that case, the controller 121 transmits the encrypted data to the host 101. When the comparison result that the plaintext data and the decrypted data do not match is obtained in the comparator 130a, the controller 121 determines that the encrypted data is not valid. In that case, the controller 121 notifies the host 101 of an error without transmitting the encrypted data to the host 101.

[0041] [Operation Procedure] FIG. 4 shows the operation procedure in the semiconductor device 100a. The host 101 transmits an encryption processing instruction command and plaintext data to the security IP 102a. In the security IP 102a, the controller 121 receives the encryption processing instruction command transmitted from the host 101 (step B1). The controller 121 transfers the plaintext data added to the encryption processing instruction command to the encryption module 125a (step B2).

[0042] The encryption module 125a stores the transferred plaintext data in the buffer 126. In the encryption module 125a, when the Verification function is not enabled, the selector 128 selects the path of the buffer 126. The encryption processing unit 127 encrypts the plaintext data stored in the buffer 126, which is input via the selector 128 (step B3). The encryption processing unit 127 transfers the encrypted data encrypted in step B3 to the comparator 130a (step B4). The comparator 130a stores the transferred encrypted data in the register X132.

[0043] The controller 121 determines whether a fault injection has been detected (step B5). If it is determined in step B5 that no fault injection has been detected, the controller 121 reads out the encrypted data stored in the register X132 of the comparator 130a. The controller 121 transmits the read encrypted data to the host 101 (step B10). The host 101 acquires the encrypted data from the security IP 102a. Steps B1 - B5, and step B10 may be the same as steps A1 - A5, and A10 shown in FIG. 2.

[0044] If it is determined in step B5 that a fault injection has been detected, the verification unit 123 of the controller 121 enables the Verification function. Also, the controller 121 changes the select signal output to the selector 128. Due to the change of the select signal, the selector 128 selects the path of the data input from the controller 121. The controller 121 reads out the encrypted data stored in the register X132, and inputs the read encrypted data to the selector 128. Also, the controller 121 instructs the encryption module 125a to decrypt the encrypted data. The encryption processing unit 127 decrypts the encrypted data input via the selector 128 (step B6). The encryption processing unit 127 transfers the decrypted data decrypted in step B6 to the comparator 130a (step B7). In the comparator 130a, the register Y133 stores the transferred decrypted data.

[0045] The controller 121 reads the plaintext data from the buffer 126 of the encryption module 125a and transfers the read plaintext data to the comparator 130a. The comparator 130a compares the plaintext data transferred by the controller 121 with the decrypted data transferred in step B7 (step B8). The verification unit 123 reads the comparison result of the comparator 130a and determines whether the plaintext data and the decrypted data match (step B9). If the verification unit 123 determines that the plaintext data and the decrypted data do not match, it determines that the encrypted data is not legitimate and determines that a fault injection attack has been performed. In that case, the controller 121 notifies the host 101 of an error (step B11). If the verification unit 123 determines in step B9 that the plaintext data and the decrypted data match, it determines that a fault injection has been misdetected due to noise or the like. In that case, the process proceeds to step B10, and the controller 121 transmits the encrypted data to the host 101.

[0046] [Summary] In the present embodiment, when a fault injection is detected, the encryption module 125a verifies the validity of the encrypted data by the Verification method. The encryption module 125a only needs to decrypt the encrypted data when a fault injection is detected by the fault injector 103, and it is not necessary to always decrypt the encrypted data. Therefore, the present embodiment can suppress a decrease in the arithmetic performance in the encryption module 125a when no fault injection is detected. In the present embodiment, the security IP 102 can distinguish between a false detection caused by noise and a detection caused by a fault injection attack by combining the detection result of the fault injector 103 and the verification result of the encrypted data. Therefore, the present embodiment can suppress a false detection of a fault injection while suppressing a decrease in the arithmetic performance in the encryption processing unit.

[0047] [Modification Example] In the above-described Embodiment 1 and Embodiment 2, an example was described in which the controller 121 of the security IP 102 is notified that a fault injection has been detected via the host 101. However, the present disclosure is not limited to this. The detection of a fault injection may be notified directly to the controller 121, for example, from the fault injection detector 103 without going through the host 101.

[0048] Also, in the present disclosure, the fault injection detector 103 may be implemented corresponding to a module targeted by a fault injection attack, such as the security IP 102. For example, the fault injection detector 103 may be implemented inside the module targeted by the fault injection attack. Alternatively, the fault injection detector 103 may be implemented near the module targeted by the fault injection attack, for example, at a location within a predetermined distance from the module.

[0049] FIG. 5 shows a configuration example of a semiconductor device according to a modification. In this modification, the fault injection detector 103 is implemented inside the security IP 102. The fault injection detector 103 outputs a fault detection signal to the controller 121 within the security IP 102. When the fault detection signal is output, the controller 121 performs the operations described in Embodiment 1. The configuration in which the fault injection detector 103 is implemented inside the security IP 102 is useful for an attack directly on the security IP 102, for example, an attack in which electromagnetic waves are irradiated on the security IP 102.

[0050] The fault injection detector 103 may be implemented inside or in the vicinity of the security IP 102a in the semiconductor device 100a in Embodiment 2 shown in FIG. 3. In that case, the fault injection detector 103 may output a fault detection signal to the controller 121 within the security IP 102a. When the fault detection signal is output, the controller 121 performs the operations described in Embodiment 2.

[0051] As described above, the invention made by the present inventor has been specifically described based on the embodiments. However, the present invention is not limited to the embodiments already described, and it goes without saying that various modifications are possible without departing from the gist thereof.

Explanation of Reference Numerals

[0052] 100: Semiconductor device 101: Host 102: Security IP 103: Fault injection detector 121: Controller 122: Command reception unit 123: Verification unit 125: Encryption module 126: Buffer 127: Encryption processing unit 128: Selector 130: Comparator 131: Register 132: Register X 133: Register Y

Claims

1. A fault injection detector for detecting a fault injection, an encryption module for generating first encrypted data by encrypting plaintext data, and a controller for verifying the first encrypted data generated by the encryption module and determining whether the first encrypted data is valid when the fault injection is detected by the fault injection detector. A semiconductor device comprising the same.

2. The semiconductor device according to claim 1, wherein the controller verifies the first encrypted data when the fault injection is detected when the first encrypted data is generated by the encryption module.

3. When the fault injection is detected, the encryption module generates second encrypted data by encrypting the plaintext data, The semiconductor device according to claim 1, wherein the controller verifies the first encrypted data based on a comparison result between the first encrypted data and the second encrypted data.

4. The semiconductor device according to claim 3, wherein the controller determines that the first encrypted data is valid when the first encrypted data and the second encrypted data match.

5. The encryption module includes a buffer for storing the plaintext data, an encryption processing unit for generating the first encrypted data and the second encrypted data by encrypting the plaintext data stored in the buffer, and a comparator for comparing the first encrypted data and the second encrypted data. The semiconductor device according to claim 3.

6. When the fault injection is detected, the encryption module generates decrypted data by performing a decryption process on the first encrypted data, The semiconductor device according to claim 1, wherein the controller verifies the first encrypted data based on a comparison result between the plaintext data and the decrypted data.

7. The semiconductor device according to claim 6, wherein the controller determines that the first encrypted data is valid when the plaintext data and the decrypted data match.

8. The encryption module includes a buffer for storing the plaintext data, An encryption processing unit that generates the first encrypted data by encrypting the plaintext data stored in the buffer, and generates the decrypted data by decrypting the first encrypted data; A selector that selectively inputs the plaintext data and the first encrypted data to the encryption processing unit; The semiconductor device according to claim 6, further comprising a comparator that compares the plaintext data and the decrypted data.

9. A host that transmits an encryption processing instruction command and the plaintext data to the controller; The semiconductor device according to claim 1, wherein when it is determined that the first encrypted data is valid, the controller transmits the first encrypted data to the host.

10. The semiconductor device according to claim 9, wherein when it is determined that the first encrypted data is not valid, the controller does not transmit the first encrypted data to the host.

11. The semiconductor device according to claim 1, wherein the fault injection detector is implemented corresponding to an external interface of the semiconductor device.

12. The semiconductor device according to claim 1, wherein the fault injection detector is implemented corresponding to a module targeted by a fault injection attack.

13. Generating first encrypted data by encrypting plaintext data; Detecting a fault injection; A fault injection determination method, comprising: in response to detecting the fault injection, verifying the generated encrypted data and determining whether the encrypted data is valid.